Privacy Policy

Last updated: June 25, 2026

In plain terms

BrainDump is built local-first. Your notes and the things you create live on your device and sync through your own private iCloud account, which the developer cannot access. AI features work one of two ways, and you choose: Bring Your Own Key, where requests go straight from your device to OpenRouter with your own API key and never touch a BrainDump server; or Managed, a paid subscription where requests are relayed through BrainDump's backend so you don't need a key. This page explains what stays on your device, exactly what leaves it under each option, and the permissions BrainDump asks for.

What's stored on your device

This data is stored locally and, if you are signed into iCloud, synced across your own devices using Apple's CloudKit in your private iCloud database. It is governed by Apple's privacy policy. The developer has no access to your iCloud data.

Calendar and Reminders

When you grant access, BrainDump reads and writes your Calendar events and Reminders through Apple's EventKit so the agent can create and update them for you. That information lives in Apple's Calendar and Reminders stores on your device and your iCloud. When a request needs schedule context, relevant items may be sent to the AI as described below.

AI features and third parties

When you use an AI feature (for example, processing a dump, generating an overview, or chatting with the agent), the content needed for that request leaves your device. Depending on what you ask, this can include:

Your voice recordings and photos are never sent, dictation and image recognition run on your device, and only the resulting text and image labels are included.

Where that content goes depends on which option you chose:

Bring Your Own Key. Requests go directly from your device to OpenRouter using an API key that you provide, and from there to the model provider you select. They are not routed through any server operated by the developer, and the content is processed under OpenRouter's privacy policy and your chosen provider's. If you have no key and no Managed subscription, AI features are turned off and no content is sent anywhere.

Managed. With a Managed subscription, the same content is sent over a secure connection to BrainDump's backend, which relays it to the model provider; this is what lets Managed work without your own key. The backend authenticates your device and subscription using Apple's App Attest and your signed App Store purchase, it does not receive your name, email, Apple ID, or any account identifier, so requests are not tied to your identity. This content is used only to provide the AI feature you requested, and is not used for advertising, profiling, or cross-app tracking.

On Managed, BrainDump's backend does not store or log the content of your requests: it relays each one and keeps nothing afterward, and it routes only to zero-data-retention model endpoints so the model provider does not retain it either. The only thing recorded is anonymous usage metering, counts such as the tokens used and which model ran, never your content, to operate your subscription and prevent abuse.

Your API key

If you use Bring Your Own Key, your OpenRouter API key is stored securely in your device's Keychain. It is used only to authenticate your own requests to OpenRouter and is never transmitted to the developer. Managed subscribers don't need a key.

Permissions BrainDump may request

Each permission is optional and used only for the feature it enables. You can change any of them in the system Settings app.

The website waitlist

This website offers an optional waitlist so we can tell you when BrainDump is available. The data practices above describe the app; the waitlist is a separate, voluntary signup on this site. If you choose to join:

You can unsubscribe at any time, and you can ask us to delete your email from the list by emailing minutes.undue.23@icloud.com. If you never join the waitlist, none of this applies to you.

What we don't do

Data retention and deletion

Because your data lives on your device and in your iCloud, you control it. You can delete individual notes and items in the app, remove your API key in Settings, turn off iCloud sync for BrainDump in the system Settings, and delete the app to remove its local data. To remove iCloud copies, delete the items in the app while signed in, or manage app data in your iCloud settings.

Children

BrainDump is not directed to children and does not knowingly collect personal information from children.

Changes to this policy

If this policy changes, the updated version will be posted here with a new "last updated" date.

Contact

Questions about privacy? Email minutes.undue.23@icloud.com.